We're calling on all EU-based Mozillians with iOS or iPadOS devices to help us monitor Apple’s new browser choice screens. Join the effort to hold Big Tech to account!

ابحث في الدعم

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

My malware app is reporting a Trojan.YZST.9002 loaded from Firefox executables

  • 4 ردود
  • 0 have this problem
  • 1 view
  • آخر ردّ كتبه Jim

more options

My System Mechanic malware search system has quarantined a virus located in two Firefox locations: Virus is W32/Trojan.YZST-9002 LOCATE IN: C:/PROGRAM FILES/MOZILLA FIREFOX/UNINSTALL/HELPER.EXE C:/PROGRAMFILES/MOZILLA FIREFOX/MAINTENANCE SERVICES_UNINSTALL... I will use the delete process and remove them and watch for future loads.

My System Mechanic malware search system has quarantined a virus located in two Firefox locations: Virus is W32/Trojan.YZST-9002 LOCATE IN: C:/PROGRAM FILES/MOZILLA FIREFOX/UNINSTALL/HELPER.EXE C:/PROGRAMFILES/MOZILLA FIREFOX/MAINTENANCE SERVICES_UNINSTALL... I will use the delete process and remove them and watch for future loads.

الحل المُختار

I will close this for now and see if I have any future incidents. Thanks, Jim

Read this answer in context 👍 0

All Replies (4)

more options

I have been using System Mechanic for many years now and it just recently found two files named above within mozilla folders. They had been moved to quarantine and I deleted them yesterday. I did see one reference to the files via google so will leave this out there in case others see it.

more options

Those files are quite normal on Windows. UNINSTALL/HELPER.EXE is the uninstaller for Firefox.

MAINTENANCE SERVICES_UNINSTALL is the uninstaller for the Mozilla Maintenance Service that is used to update Firefox in the background.

Both these files interact with the program folder, so that might alert System Mechanic.

more options

I wonder why System Mechanic only recently thought the two normal things are trojans though, besides being false positives hmm.

Modified by James

more options

الحل المُختار

I will close this for now and see if I have any future incidents. Thanks, Jim